Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2014-1517
Description:The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related to a "login CSRF" issue.
Test IDs: 1.3.6.1.4.1.25623.1.0.867745   1.3.6.1.4.1.25623.1.0.867769   1.3.6.1.4.1.25623.1.1.10.2014.0200  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2014-1517
http://lists.fedoraproject.org/pipermail/package-announce/2014-April/132281.html
http://lists.fedoraproject.org/pipermail/package-announce/2014-April/132309.html
http://www.securitytracker.com/id/1030128




© 1998-2025 E-Soft Inc. All rights reserved.